Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
903 results
CVE-2024-29269 preview

CVE-2024-29269

GitHubdkstar11q/cve-2024-29269

Exploit for CVE-2024-29269 enabling unauthenticated OS command execution on TLR-2005KSH routers, with ZoomEye and Leakix dork queries for target…

embedded-systems-securityexploitationinformation-gathering+5
1 year ago
CVE-2026-94095 preview

CVE-2026-94095

GitHubhackspeak/cve-2026-94095

PoC for CVE-2026-94095, a traceroute command injection in Netcore NBR200V2 firmware via ubus JSON-RPC, enabling root RCE for authorized testing.

embedded-systems-securityexploitationhardware-iot-security+5
11 day ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
11 month ago
LoongBleed preview

LoongBleed

GitHubjiegec/loongbleed

Proof-of-concept demonstrating a microarchitectural data leak in Loongson LA464/LA664 processors via undefined upper bits of LASX vector registers,…

educationembedded-systems-securityexploitation+4
171 month ago
CVE-2026-93958 preview

CVE-2026-93958

GitHubhackspeak/cve-2026-93958

Authenticated command injection PoC for D-Link R95/BE9500 DHMAPI SetTimeSettings, achieving root RCE via NTPServer backtick injection, with full…

command-and-controlembedded-systems-securityexploitation+7
12 days ago
CVE-2026-78306 preview

CVE-2026-78306

GitHubwh02m1/cve-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

bluetooth-securityembedded-systems-securityexploitation+6
2 days ago
rp2350_hacking_challenge preview

rp2350_hacking_challenge

GitHubraspberrypi/rp2350_hacking_challenge

Raspberry Pi RP2350 hacking challenge: extract a 128-bit OTP secret protected by secure boot and OTP lock, with setup scripts and firmware for Pico 2…

cryptographyctfeducation+5
2021 year ago
zte-blade-v40-vita-unlock preview

zte-blade-v40-vita-unlock

GitHubredzrush101/zte-blade-v40-vita-unlock

Unlocking the ZTE Blade V40 Vita (P606F02 / Unisoc UMS9230 / UFS) bootloader via CVE-2022-38694 - Linux scripts, the FBE post-unlock hang fix, and…

android-securityembedded-systems-securityexploitation+6
7 days ago
ghostlock-sabrina preview

ghostlock-sabrina

GitHubk-o-n-t-o-r/ghostlock-sabrina

CVE-2026-43499 GhostLock root exploit for Chromecast with Google TV (sabrina)

android-securitybinary-exploitationembedded-systems-security+6
18 days ago
CVE-2026-79551-Tenda preview

CVE-2026-79551-Tenda

GitHubsnyi001/cve-2026-79551-tenda

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

cryptographyembedded-systems-securityfirmware-analysis+6
7 days ago
sony-bravia-root-toolkit preview

sony-bravia-root-toolkit

GitHubsaaedimam/sony-bravia-root-toolkit

CVE-2019-2215 & DirtyCOW exploit automation + post-root debloat + Magisk modules for Sony BRAVIA KDL-43W800C

embedded-systems-securityexploitationhardware-iot-security+6
18 days ago
cve-2026-43499-firetv-sheldonp-writeup preview

cve-2026-43499-firetv-sheldonp-writeup

GitHubaccessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock.

android-securityeducationembedded-systems-security+7
7 days ago
KernelPatch preview

KernelPatch

GitHubbmax121/kernelpatch

Patching and hooking the Linux kernel with only a stripped Linux kernel image.

android-securitybinary-analysisbinary-exploitation+7
1.5k21 days ago
KernelPatch preview

KernelPatch

GitHublyravoid/kernelpatch

Patches and hooks the Linux kernel using only a stripped kernel image, extracting symbols and injecting code for inline and syscall hooking on arm64.

android-securitybinary-analysisbinary-exploitation+6
1023 days ago
Vulnerability-DLink-CVE-2025-14659 preview

Vulnerability-DLink-CVE-2025-14659

GitHubpeterlinccl/vulnerability-dlink-cve-2025-14659

Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in…

embedded-systems-securityexploitationfirmware-analysis+6
10 days ago
infected-drones preview

infected-drones

GitHubnicholasaleks/infected-drones

A collection of vulnerabilities & exploits against modern GCS

educationembedded-systems-securityexploitation+5
2111 days ago
cve-2026-86547-mrubyc-op-enter preview

cve-2026-86547-mrubyc-op-enter

GitHubharshrajsinghania/cve-2026-86547-mrubyc-op-enter

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

embedded-systems-securityexploitationfuzzing+3
11 days ago
ane preview

ane

GitHubeiln/ane

Reverse engineered Linux kernel driver and userspace library for the Apple Neural Engine (ANE), enabling hardware access and analysis on Linux…

ai-securitybinary-analysisembedded-systems-security+3
5352 years ago
Previous12…51Next